Impact
An escalated hypervisor call in IBM PowerVM can be triggered by a privileged guest with root access. The attacker crafts an input that causes a virtual processor to become permanently unresponsive, forcing a full platform restart. In certain situations the malicious input may also place a small, attacker‑controlled data fragment in hypervisor or partition memory, which can lead to integrity compromise. The effect is a loss of availability for the entire system and a potential integrity breach of protected data.
Affected Systems
Affected products include IBM PowerVM Hypervisor firmware versions FW1110.00 through FW1110.30, FW1120.00, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2. These firmware bundles support a range of IBM Power System models such as Power 11 E1180, S1122/S1124/S1122s/S1114/L1122/L1124/E1150, Power 10 E1080, S1022/S1024/S1022s/S1014/L1022/L1024/E1050/S1012, and Power 9 S922/H922/S914/S924/H924/E950/E980. The vulnerability exists across all these models and firmware versions listed and applies to any guest partition that can attain root access.
Risk and Exploitability
With a CVSS score of 7.3, the vulnerability is considered high impact. The EPSS score is not available, and the issue is not yet listed in CISA’s KEV catalog, suggesting no confirmed public exploitation at the time of this advisory. Successful exploitation requires root privilege inside a guest partition, implying that attackers already have significant local compromise. The exploit can be carried out through a crafted hypervisor call, without needing network or physical access to the host. Organizations should assume that the likelihood of exploitation is moderate under the stated conditions, and the integrity and availability damage could be critical to mission‑critical workloads.
OpenCVE Enrichment